its been a while since I've worked with splunk
I have an error detail that I can search in splunk:
index=* errorMessage
and it returns:
dateTime - sessionId - errorMessage
if I search the sessionId I get:
index=* sessionId
dateTime - sessionId - customerDetail
How can I find the customerDetail using one query by searching for the errorMessage?
A subsearch should handle that.
index=* sessionId [index=* errorMessage | fields sessionId | format]
I hope you are using real index names in your queries as index=* is very inefficient.